Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2345

Browse all 2345 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2026-60080 Apache Fory: Rust MetaString heap use-after-free — Apache Fory CWE-416 - - 2026-07-21
CVE-2026-64606 Apache Fory, Apache Fory: Class-registration bypass through an auto-admitted SerializedLambda capturing interface — Apache Fory CWE-502 - - 2026-07-21
CVE-2026-64609 Apache Fory, Apache Fory: Out-of-Bounds Read via sun.misc.Unsafe in zero-copy java deserialization — Apache Fory CWE-125 - - 2026-07-21
CVE-2026-64608 Apache Fory: Heap type confusion and out-of-bounds read/write in C++ compatible-mode field-skip paths — Apache Fory CWE-843 - - 2026-07-21
CVE-2026-56623 Apache MINA SSHD: Path traversal in org.apache.sshd:sshd-git on Windows — Apache MINA SSHD CWE-22 7.1 High 2026-07-20
CVE-2026-56624 Apache MINA SSHD: SSH certificate options lack validations — Apache MINA SSHD CWE-295 7.3 High 2026-07-20
CVE-2026-58624 Apache MINA SSHD: Remote execution of JGit commands can write files on the server — Apache MINA SSHD CWE-20 5.4 Medium 2026-07-20
CVE-2026-56452 Apache MINA SSHD: Path traversal in SCP file reception — Apache MINA SSHD CWE-22 7.5 High 2026-07-20
CVE-2026-62418 Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources check — Apache Syncope CWE-918 - - 2026-07-20
CVE-2026-62183 Apache Syncope: User self-service privilege escalation — Apache Syncope CWE-269 - - 2026-07-20
CVE-2026-57308 Apache Syncope: SQL injection vulnerability in Audit Events search — Apache Syncope CWE-89 - - 2026-07-20
CVE-2026-53421 Apache Syncope: Remote Code Execution via Scripted Connector — Apache Syncope CWE-653 - - 2026-07-20
CVE-2026-53405 Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask — Apache Syncope CWE-653 - - 2026-07-20
CVE-2026-63071 Apache Syncope: RCE via Groovy Sandbox bypass — Apache Syncope CWE-653 - - 2026-07-20
CVE-2026-59173 Apache Traffic Server: DoS vulnerability in HTTP/2 via stalled flow-control conditions — Apache Traffic Server CWE-400 - - 2026-07-18
CVE-2026-62764 Apache Accumulo: A user can trigger a graceful shutdown of services without the relevant system permissions — Apache Accumulo CWE-274 - - 2026-07-17
CVE-2026-26032 Apache Ivy: PackagerResolver path traversal vulnerability — Apache Ivy CWE-22 - - 2026-07-15
CVE-2026-57821 Apache Fineract: Office list: SQL Injection via Subquery in orderBy — Apache Fineract CWE-89 - - 2026-07-15
CVE-2026-35152 Apache Fineract: SQL injection in runreports endpoint — Apache Fineract CWE-89 - - 2026-07-15
CVE-2026-56287 Apache Fineract: Boolean SQL Injection in Client Search API (orderBy parameter) leading to Local File Disclosure — Apache Fineract CWE-89 - - 2026-07-15
CVE-2026-49488 Apache OpenMeetings: Arbitrary File Read — Apache OpenMeetings CWE-22 - - 2026-07-14
CVE-2026-62393 Apache Kylin: Improper authorization in job information retrieval — Apache Kylin CWE-280 - - 2026-07-14
CVE-2026-62392 Apache Kylin: OS Command Injection via Async Query API — Apache Kylin CWE-78 - - 2026-07-14
CVE-2026-62390 Apache Kylin: SQL Injection Vulnerability in Catalog Cache Refresh API — Apache Kylin CWE-89 - - 2026-07-14
CVE-2026-58319 Apache Doris: Improper Authentication in Frontend HTTP API — Apache Doris CWE-306 - - 2026-07-14
CVE-2026-59084 Apache Tomcat: EncryptInterceptor requirements not clearly documented — Apache Tomcat CWE-1059 - - 2026-07-14
CVE-2026-59083 Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass — Apache Tomcat CWE-177 - - 2026-07-14
CVE-2026-59245 Apache Airflow FAB provider: FAB auth manager: a DAG named "DAGs" hijacks the global all-DAGs permission (access_control privilege escalation via resource_name() collision) — Apache Airflow FAB provider CWE-269 - - 2026-07-13
CVE-2026-58065 Apache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, disabling SSH host-key verification — Apache Airflow Git provider CWE-322 - - 2026-07-13
CVE-2026-41041 Apache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP REST client f-string URL construction, enabling path traversal to unintended API endpoints. — Apache Gravitino CWE-177 - - 2026-07-13

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.